RE: Anyone see a security issue with CHGJOBDJOBD(QSYS/QSTRUPJD) USER(GODLIKE)?

[email protected]
Newsgroups gmane.comp.systems.as400.security
Message-ID <OFEDDCACED.D4A7CFE8-ON05256F8E.004B90B8-05256F8E.004C1B27@dekko.com>
Eduard,

I like your technique and I will use it.  I will have my own QSTRUP call 
the one in QSYS first.  Then it will execute it's thing, but with adopted 
authority.  This way I will get any new updates that IBM decides to add in 
QSYS/QSTRUP, and, if I put on a new release I don't have to worry about 
changing any job descriptions, changing the authority on QSYS/QSTRUP, etc.

I have one question about this.  I planned on using the technique that IBM 
uses in their QSTRUP to start writers.
     QSYS/RTVSYSVAL SYSVAL(QSTRPRTWTR) RTNVAR(&STRWTRS)
     IF COND(&STRWTRS = '0') THEN(GOTO CMDLBL(NOWTRS))
     CALL PGM(QSYS/QWCSWTRS)
     MONMSG MSGID(CPF0000)
NOWTRS:

But if I previously called QSYS/QSTRUP I want to make sure that QSTRPRTWTR 
is not reset by that.  So, at what point does that get reset?  This is not 
a system value you can do CHGSYSVAL on.  Just want to make sure that if I 
am doing some special IPL that I don't start the printer writers 
unnecessarily.

Rob Berendt
-- 
Group Dekko Services, LLC
Dept 01.073
PO Box 2000
Dock 108
6928N 400E
Kendallville, IN 46755
http://www.dekko.com





"Eduard van den Braken" <[email protected]> 
Sent by: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
01/18/2005 03:38 AM
Please respond to
Security Administration on the AS400 / iSeries  <security400-Zwy7GipZuJhWk0Htik3J/[email protected]>


To
"Security Administration on the AS400 / iSeries" 
<security400-Zwy7GipZuJhWk0Htik3J/[email protected]>
cc

Subject
RE: [Security400] Anyone see a security issue with 
CHGJOBDJOBD(QSYS/QSTRUPJD) USER(GODLIKE)?






Think about this

Create a new STARTUP CL-program in QGPL or a Tools library.
Call the original QSTRUP in QSYS (thus al the release changes are
allways honored)
Put your extra actions in the STARTUP program.

This way after a release update all the new stuff does start, maybe you
will try to start something which is already started, but that should be
no problem


===================================================
Met vriendelijke groet,
Inter Access BV

Eduard van den Braken
Technisch Consultant iSeries

E-mail:  [email protected]


-----Oorspronkelijk bericht-----
Van: security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]
[mailto:security400-bounces-Zwy7GipZuJhWk0Htik3J/[email protected]] Namens Mayer, Michael (CMA
Consulting)
Verzonden: maandag 17 januari 2005 19:37
Aan: 'Security Administration on the AS400 / iSeries'
Onderwerp: RE: [Security400] Anyone see a security issue with
CHGJOBDJOBD(QSYS/QSTRUPJD) USER(GODLIKE)?

Exactly why our startup program is also in QGPL!

-----Original Message-----
From: Sean Porterfield [mailto:sporter-D/nQUwvqDXRWk0Htik3J/[email protected]] 
Sent: Monday, January 17, 2005 1:47 PM
To: Security Administration on the AS400 / iSeries
Subject: Re: [Security400] Anyone see a security issue with
CHGJOBDJOBD(QSYS/QSTRUPJD) USER(GODLIKE)?

Edwin Davidson wrote:

> We did this because last time we upgraded the OS, QSTRUP got replaced 
> with a new clean version.  We had
> to restore QSTRUP from backup.


That's why we put our QSTRUP in QGPL.  IBM gets to replace the QSYS 
version every upgrade, we check for changes that we need to make, our 
copy stays the same.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400)
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) 
mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.